Skip to main content

Software intelligence

W3 Total Cache vulnerabilities

35 tracked advisories · slug w3-total-cache

Important: W3 Total Cache appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works

Tracked advisories

35

Latest advisory

21 August 2026

CISA KEV matches

0

In this WordPress feed

WordPress slug

w3-total-cache

Plugin

What this means for W3 Total Cache

This catalog lists 35 known advisories affecting W3 Total Cache. The most recent was published on 21 August 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.

Latest issues

  • W3 Total Cache < 2.10.5 - Unauthenticated Path Traversal

    May allow reading or writing files outside intended directories.

    Published 21 August 2026

  • W3 Total Cache <= 2.10.3 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name

    May allow attackers to run scripts in visitors' browsers or hijack admin sessions.

    Published 13 August 2026

  • W3 Total Cache <= 2.10.2 - Unauthenticated Path Traversal

    May allow reading or writing files outside intended directories.

    Published 31 July 2026

Vulnerability types

  • Cross-site scripting8
  • Directory traversal3
  • Remote code execution2
  • CSRF1

Authentication (inferred from titles)

  • Unauthenticated9
  • Authenticated3
  • Unspecified23

Advisory history

Known W3 Total Cache advisories published by month.

All advisories

1630 of 35

2 / 3

Check whether your installed version is affected

SiteRespond Defence matches your installed W3 Total Cache version against this catalog when the Defence plugin is connected to your WordPress site.